Between: Ryburn Commercial Services Ltd (Company No. 13511979), 2 Stones Drive, Ripponden, HX6 4NY ("Processor", "we", "us") and the Subscriber identified in their Notis account ("Controller", "you").
This Data Processing Addendum ("DPA") forms part of, and is incorporated by reference into, the Notis Terms of Service. It applies where we process personal data on your behalf as a Data Processor, specifically in relation to Contract Data you enter into the Service which may contain personal data relating to third parties (such as project managers, employer's agents, and other named contacts on your NEC4 contracts).
1. Definitions
Terms not defined in this DPA have the meanings given in the Notis Terms of Service. In addition:
- "UK GDPR" means the UK General Data Protection Regulation as it forms part of domestic law in the United Kingdom.
- "Data Protection Legislation" means the UK GDPR, the Data Protection Act 2018, and any successor legislation.
- "Personal Data", "Processing", "Data Controller", and "Data Processor" have the meanings given in the UK GDPR.
- "Sub-processor" means any third party engaged by us to process Personal Data on your behalf in providing the Service.
2. Roles of the Parties
2.1 In respect of Contract Data containing Personal Data of third parties (e.g. named individuals at the Project Manager's organisation, the Employer, or subcontractors), you are the Data Controller and we are the Data Processor.
2.2 In respect of your own Account Data (your name, email, organisation details, and billing information), we are the Data Controller, as set out in our Privacy Policy at notis.solutions/privacy. This DPA does not apply to that processing.
3. Our Obligations as Processor
In respect of Personal Data we process on your behalf as Controller, we shall:
3.1 Process Personal Data only on your documented instructions, which shall be to provide the Service as described in the Terms of Service, unless required to do otherwise by UK law (in which case we will inform you of that legal requirement before processing, unless the law prohibits this).
3.2 Ensure that persons authorised to process the Personal Data are subject to appropriate confidentiality obligations.
3.3 Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Section 9 of our Privacy Policy.
3.4 Not engage another processor (Sub-processor) without your prior general authorisation, which you provide by accepting this DPA in respect of the Sub-processors listed in Clause 6, and give you the opportunity to object to any new Sub-processor as described in Clause 6.3.
3.5 Assist you, taking into account the nature of the processing, by appropriate technical and organisational measures, insofar as reasonably possible, to respond to requests from data subjects exercising their rights under the Data Protection Legislation.
3.6 Assist you in ensuring compliance with your obligations regarding security of processing, notification of personal data breaches, and data protection impact assessments, taking into account the nature of processing and information available to us.
3.7 At your election, delete or return all Personal Data to you after the end of the provision of the Service, and delete existing copies, in accordance with the data retention terms set out in Section 6 (Data Retention) of our Privacy Policy — save where UK law requires storage of the Personal Data.
3.8 Make available to you all information reasonably necessary to demonstrate compliance with the obligations in this Clause 3, and allow for and contribute to audits, including inspections, conducted by you or an auditor mandated by you, subject to reasonable notice and confidentiality safeguards, and no more than once in any 12-month period except where required by a regulator or following a security incident.
4. Your Obligations as Controller
You warrant that:
4.1 You have a lawful basis under the Data Protection Legislation for any Personal Data you input into the Service, including any Personal Data relating to third parties contained within Contract Data.
4.2 You have provided any necessary notices to, and where required obtained any necessary consents from, third parties whose Personal Data you input into the Service (for example, named individuals at the Project Manager's organisation).
4.3 Your instructions to us for the processing of Personal Data (i.e., your use of the Service in the ordinary course) comply with the Data Protection Legislation.
5. Security Incidents
5.1 We shall notify you without undue delay upon becoming aware of a Personal Data breach affecting Personal Data processed on your behalf, providing you with sufficient information to allow you to meet any obligations to report or inform data subjects of the breach under the Data Protection Legislation, to the extent this information is available to us.
5.2 We shall take reasonable steps to contain and remediate any such breach.
6. Sub-processors
6.1 You provide general authorisation for us to engage the following Sub-processors in connection with the Service, each of whom is bound by data processing terms no less protective than this DPA:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database and file storage (Contract Data) | UK (London) |
| Clerk | Authentication and account management | United States |
| Stripe | Payment processing | United States / EEA |
| Anthropic | AI-assisted notice drafting | United States |
| Resend | Transactional email delivery | United States |
6.2 An up-to-date list of Sub-processors will be maintained at notis.solutions/dpa (or by request to hello@notis.solutions).
6.3 We shall notify you of any intended changes concerning the addition or replacement of Sub-processors, giving you the opportunity to object on reasonable data protection grounds within 14 days of notification. If you object and we cannot reasonably address your objection, either party may terminate the affected part of the Service.
7. International Transfers
7.1 Where a Sub-processor is located outside the UK, transfer of Personal Data to that Sub-processor is protected by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or another mechanism recognised as adequate under the Data Protection Legislation, as set out against each Sub-processor in Clause 6.1 and further described in our Privacy Policy.
7.2 We shall ensure such safeguards remain in place for the duration of the relevant Sub-processor's engagement.
8. Liability
8.1 Each party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in Section 10 (Limitation of Liability) of the Terms of Service.
8.2 Nothing in this DPA relieves either party of its own direct obligations and liability under the Data Protection Legislation.
9. Duration and Termination
This DPA remains in effect for as long as we process Personal Data on your behalf under the Terms of Service, and terminates automatically upon termination of your subscription, subject to Clause 3.7 (deletion or return of data).
10. Order of Precedence
In the event of a conflict between this DPA and the Terms of Service in respect of the processing of Personal Data, this DPA shall prevail.
11. Governing Law
This DPA is governed by the laws of England and Wales, consistent with Clause 12 (Governing Law and Disputes) of the Terms of Service.
12. Contact
Questions about this DPA or our data processing practices can be directed to hello@notis.solutions.